The Answers You Need After an Alert
Attacks often start 11 days before detection.
You need to know what happened before an EDR alert:
- Exfiltration: Was IP or sensitive data stolen?
- Lateral Movement: Were other hosts involved?
- Command and Control: Does the attacker have remote access?
Our service gives you all the answers you need in one report.
Why Sleuth Kit Labs
The team behind Autopsy, Cyber Triage, and Sleuth Kit Labs has been conducting investigations and building digital forensics tools for over 20 years.

Brian Carrier, CEO
Brian leads the company and has been involved with national security investigations, built leading open source tools, and wrote the popular book, File System Forensic Analysis.

Mike Wilkinson, Head of Services and Training
Mike leads services efforts with knowledge from over two decades of experience conducting digital investigations and helping people recover from cyber security incidents.
Pricing and Delivery
Pricing | Fixed price of $2,000 for each endpoint* |
Delivery | 1 business day target.** |
*Additional support post-report is billed at an hourly rate.
**Estimated date subject to change based on workload. An estimate will be provided upon purchase.
Bulk discounts available for MSSPs and MDRs.
White labeling is possible.
Request Information: